Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wpj8-2grx-f965

Опубликовано: 15 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

EPSS

Процентиль: 5%
0.00026
Низкий

7.4 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 1 года назад

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

CVSS3: 7.4
nvd
больше 1 года назад

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

CVSS3: 7.4
debian
больше 1 года назад

An improper certificate validation issue in Smartcard authentication i ...

CVSS3: 8.1
fstec
больше 1 года назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с некорректной проверкой сертификата при аутентификации по смарт-картам, позволяющая нарушителю пройти проверку подлинности как другой пользователь

EPSS

Процентиль: 5%
0.00026
Низкий

7.4 High

CVSS3

Дефекты

CWE-295